4.3
CVSSv2

CVE-2015-1236

Published: 19/04/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome prior to 42.0.2311.90, allows remote malicious users to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

canonical ubuntu linux 14.10

canonical ubuntu linux 14.04

canonical ubuntu linux 15.04

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in Oxide ...
Several vulnerabilities were discovered in the chromium web browser CVE-2015-1235 A Same Origin Policy bypass issue was discovered in the HTML parser CVE-2015-1236 Amitay Dobo discovered a Same Origin Policy bypass in the Web Audio API CVE-2015-1237 Khalil Zhani discovered a use-after-free issue in IPC CVE-2015-1238 clo ...
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNodecpp in the Web Audio API implementation in Blink, as used in Google Chrome before 420231190, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element ...